Weaknesses of type CWE-200

4,948 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-2487MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-5615MEDIUMOpen Graph <= 1.11.2 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2024-7426MEDIUMCommunity by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2023-39052—An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2023-49762MEDIUMWordPress AppMySite Plugin <= 3.11.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-6448MEDIUMMollie Payments for WooCommerce <= 7.7.0 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-92770HIGHHarbor through 2.15.2 Scanner Credential Disclosure via Query ParameterEPSS 0.5%CVE-2023-39045—An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2026-65613MEDIUMApache CloudStack: Webhook Deliveries Incorrect AccessEPSS 0.5%CVE-2024-6550MEDIUMGravity Forms: Multiple Form Instances <= 1.1.1 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2024-32046MEDIUMDetailed error discloses full file path with dev mode offEPSS 0.5%CVE-2026-82657HIGHAdmidio before 5.0.12 Authentication Bypass via RSS feedsEPSS 0.5%CVE-2026-69153MEDIUMPostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unsetEPSS 0.5%CVE-2026-40885HIGHgoshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized accessEPSS 0.5%CVE-2026-91965HIGHWWBN AVideo through 29.0 Broken Access Control via Live EndpointsEPSS 0.5%CVE-2025-61777CRITICALFlagForge Allows Unauthenticated Badge Template API AccessEPSS 0.5%CVE-2026-70473HIGHFlowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert historyEPSS 0.5%CVE-2026-34970MEDIUMMantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is RevokedEPSS 0.5%CVE-2021-46891—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2022-46371MEDIUMAlotcer - AR7088H-A Information disclosureEPSS 0.4%